First published: Wed Aug 22 2012(Updated: )
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, accesses files with the privileges of the root user, which allows remote authenticated users to bypass intended permission settings by requesting a file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Email and Web Security | =5.0 | |
McAfee Email and Web Security | =5.5 | |
McAfee Email and Web Security | =5.6 | |
McAfee Email Gateway | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4586 is classified as a high severity vulnerability that allows unauthorized access to files by remote authenticated users.
To fix CVE-2012-4586, upgrade McAfee Email and Web Security to version 5.5 Patch 6 or 5.6 Patch 3, or McAfee Email Gateway to version 7.0 Patch 1 or later.
CVE-2012-4586 affects users of McAfee Email and Web Security versions 5.x before 5.5 Patch 6 and 5.6 before Patch 3, as well as McAfee Email Gateway 7.0 before Patch 1.
The risks of CVE-2012-4586 include unauthorized access to sensitive files, which can lead to data breaches and compromise the security of an organization.
Yes, CVE-2012-4586 can be exploited remotely by authenticated users who can bypass permission settings to access sensitive files.